CVE-2025-37870: Linux Kernel

Medium severity, CVSS 5.5. EPSS: 0.3% chance of exploitation in the next 30 days.

In the Linux kernel, the following vulnerability has been resolved: drm/amd/display: prevent hang on link training fail [Why] When link training fails, the phy clock will be disabled. However, in enable_streams, it is assumed that link training succeeded and the mux selects the phy clock, causing a hang when a register write is made. [How] When enable_stream is hit, check if link training failed. If it did, fall back to the ref clock to avoid a hang and keep the system in a recoverable state.

Affected products

  • Linux Linux Kernel: from 6.3, before 6.12.25 (fixed in 6.12.25); from 6.13, before 6.14.4 (fixed in 6.14.4)

Published 2025-05-09. Last modified 2026-06-17.